github-cli

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates reading external data from GitHub (issues, pull requests, etc.). While this content could theoretically contain instructions to influence the agent (indirect prompt injection), the skill includes guidelines for the agent to summarize findings and verify targets, which helps maintain operational integrity.
  • Ingestion points: gh issue view, gh pr view, and gh run list commands mentioned in SKILL.md.
  • Boundary markers: Not explicitly defined for the output content.
  • Capability inventory: The skill uses the gh CLI for repository interactions.
  • Sanitization: Not explicitly implemented within the CLI instructions.
  • [COMMAND_EXECUTION]: The skill uses the official gh command-line interface. All command examples are standard usage of the tool, and the instructions prioritize read-only actions to prevent accidental or unauthorized changes to repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 08:32 PM
Security Audit — agent-trust-hub — github-cli